Privacy Policy
Privacy Policy
Document Version: XP.EN.01.03
1. General Information
Xpand IT is committed to protecting your privacy. This Privacy Policy governs our practices for collecting, using, retaining, and disclosing personal data. This policy applies to information we collect through the use of our websites, the subscription to our services or products, whether free or paid, participation in marketing campaigns, such as events and webinars, or whenever you interact with Xpand IT.
We update this Privacy Policy periodically and recommend that you review it regularly.
If our data processing practices change significantly, we will notify you of those changes before using your personal data for new purposes and, where applicable, give you the opportunity to object or withhold consent to those new processing activities.
This Privacy Policy has been prepared in accordance with the General Data Protection Regulation (GDPR) and other applicable European and Portuguese personal data protection laws.
2. General Principles of our Privacy Policy
Xpand Solutions – Informática e Novas Tecnologias, Lda., owner of the Xpand IT brand, is the entity responsible for processing personal data.
In the context of your relationship with us, whether through the use of our website, the provision of your personal data, or any other interaction involving the processing of personal data, we undertake to act in accordance with this Privacy Policy, based on the following principles:
i. Only duly authorized individuals access and process the personal data necessary to perform their duties and solely for legitimate and authorized purposes;
ii. We consider the security of personal data a priority and regularly review the implemented measures, considering technological developments and identified risks;
iii. We recognize that personal data belongs to the respective data subjects, with Xpand IT acting as the controller of that data under applicable law;
iv. We promote good practices in Privacy, Data Protection, and Information Security, reviewing them continuously as part of ongoing improvement.
3. Definitions
Personal data: any information relating to an identified or identifiable natural person (“Data Subject”). An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural, or social identity.
Processing: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Consent: any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which the data subject, by a statement or by a clear affirmative action, agrees to the processing of personal data relating to them.
Websites: all Xpand IT websites under its main domains, namely xpand-it.com.
Cookies: small text files stored on your device, such as a computer, tablet, or mobile phone, when you visit a website, allowing the device to be recognized and certain information about your use to be stored.
4. What personal data do we collect?
We collect only the categories of personal data that are adequate, relevant, and necessary for the purposes described in this Privacy Policy, namely:
- Contact details, such as name, email address, phone number, country, and city;
- Professional and profile data, such as job title, company, and other information related to professional activity;
- Photographs;
- Billing data, including tax identification number;
- Software-related preferences, including your use and interests;
- Data relating to browsing behavior on our websites;
- IP addresses, URLs visited, and other information related to the use of our websites and services;
- Cookies, under the terms of our Cookie Policy;
- Data relating to academic background and professional experience.
The personal data collected is processed electronically and stored in secure databases, in strict compliance with applicable Personal Data Protection laws and Information Security standards.
We process your personal data exclusively for specific, explicit, and legitimate purposes determined at the time of collection. Personal data will not subsequently be processed in a manner incompatible with those purposes, except where permitted by the GDPR, including for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes.
Although Xpand IT’s activities do not generally involve the intentional processing of special categories of personal data (“sensitive data”), if such processing occurs on an exceptional basis, it will only take place in the cases provided for in Article 9(2) of the GDPR and subject to the adoption of enhanced safeguards appropriate to the risk.
5. How do we collect your personal data?
We collect personal data directly from data subjects through the following activities and interaction channels:
| Activity | Data | |
| Website | All websites | Cookies |
| Webinar registration forms | Contact details and professional data | |
| Training registration forms | Contact details, professional data, and billing data | |
| Event registration forms | Contact details, professional data, and photographs taken during the event | |
| Newsletter subscription | Contact details | |
| Content downloads, such as e-books, case studies, or other materials | Contact details and professional data | |
| Access to online support | Contact details | |
| Product Sandboxes | Contact details and usage data | |
| Job application form | Contact details, résumé, and other relevant professional information | |
| Contact requests | Contact details | |
| Digital surveys and questionnaires | Contact details and software-related preferences | |
| Paper surveys and questionnaires | Contact details and software-related preferences | |
| Participation in events | Contact details and software-related preferences | |
| Recruitment activities, including when you submit an unsolicited application or apply directly for a position advertised on our website; through job fairs, events, or a third party; when you apply through referrals provided by our employees; and during interviews | Contact details, professional data, academic background, professional experience, and other information relevant to the recruitment process | |
In all cases, collection is limited to what is necessary for the applicable purpose and carried out in accordance with the principles of transparency, data minimization, and purpose limitation.
6. How do we use the data collected?
Purposes
The personal data we collect is processed for the purposes listed below, always in an appropriate and proportionate manner and limited to what is necessary:
| Purpose | Personal data processed | |
| Marketing and communication campaigns | Contact details, photographs, and software-related preferences | |
| Commercial activities, business development, and marketing | Contact details, professional data, and software-related preferences | |
| Management of the contractual relationship, where applicable | Contact details | |
| Sending important communications about changes to our terms, conditions, and policies | Contact details | |
| Identifying and exploring new market opportunities | Professional data | |
| Processing transactions and sending related information, including purchase confirmations and billing | Contact details and billing data | |
| Improving our products and services | Usage data and browsing behavior | |
| Improving the browsing experience on our websites | Cookies | |
| Recruitment and selection | Academic background, professional experience, and other information relevant to the recruitment process | |
| Improving the user experience | Anonymized usage data and aggregated product metrics | |
| Resolving technical issues and providing support | Anonymized usage data and aggregated product metrics | |
Lawful bases
Under Article 13(1)(c) of the GDPR, the processing of personal data is based on one or more lawful bases, depending on the specific purpose of the processing and the context in which the data is collected:
| Purpose | Applicable lawful basis | |
| Marketing and communication campaigns | Consent of the data subject for electronic communications / Xpand IT’s legitimate interest for non-electronic communications | |
| Commercial activities, business development, and marketing | Xpand IT’s legitimate interest | |
| Management of the contractual relationship, where applicable | Performance of a contract or pre-contractual steps | |
| Sending important communications about changes to our terms, conditions, and policies | Compliance with legal obligations | |
| Identifying and exploring new market opportunities | Xpand IT’s legitimate interest | |
| Processing transactions and sending related information, including purchase confirmations and billing | Performance of a contract / Compliance with legal obligations | |
| Improving our products and services | Xpand IT’s legitimate interest | |
| Improving the browsing experience on our websites | Consent of the data subject for non-essential cookies / Xpand IT’s legitimate interest for essential cookies | |
| Recruitment and selection | Pre-contractual steps / Consent of the data subject | |
| Improving the user experience | Xpand IT’s legitimate interest | |
| Resolving technical issues and providing support | Performance of a contract / Xpand IT’s legitimate interest | |
7. Personal data of minors
Xpand IT’s products and services are not intended for minors.
Xpand IT does not intentionally collect personal data from minors. If we become aware that personal data of a minor has been collected without the legally required consent, we will take appropriate measures to delete that data without undue delay.
If you become aware of such a situation, please contact us using the channels indicated in the “Contact us about privacy matters” section.
8. Security of personal data
We use appropriate technical and organizational measures to protect your personal data against unauthorized, accidental, or unlawful destruction, loss, alteration, disclosure, or access, as well as against any other form of unlawful processing.
The personal data provided is stored in secure systems and environments protected by appropriate security mechanisms designed to prevent unauthorized access, use, alteration, or disclosure.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including where applicable:
i. The pseudonymization and encryption of personal data;
ii. The ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
iii. The ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;
iv. A process for regularly evaluating, analyzing, and verifying the effectiveness of the technical and organizational measures implemented to ensure the security of personal data processing.
9. Sharing and disclosure of personal data
We do not share or disclose your personal data to third parties except in the cases described in this Privacy Policy or where necessary to comply with legal, regulatory, or contractual obligations.
Whenever your personal data is shared with third parties acting on our behalf, we ensure that they adopt appropriate data security and protection measures equivalent to those applied by Xpand IT. We also ensure that the necessary mechanisms are implemented to safeguard the rights of data subjects.
Depending on the purpose involved, these third parties may include, in particular, IT and hosting service providers, including cloud and hosting providers; marketing, communication, and customer relationship management platforms; entities responsible for issuing invoices and processing payments; professional advisors, including legal, accounting, or audit advisors; and public or judicial authorities, where legally required.
Social media features: Our websites may include features provided by social media networks, such as sharing buttons, links to institutional profiles, or other interactive components. These features may collect certain data, such as your IP address or information about your browsing, and may also use cookies.
These features may be hosted by third-party entities or directly on our websites. Your interactions with these features are governed by the privacy policies of the entities responsible for making them available.
Links to third-party websites: Our websites may contain links to third-party websites whose privacy practices are independent from those of Xpand IT. If you provide personal data through those websites, the relevant data will be processed in accordance with the privacy policies of those entities. We recommend that you read the relevant privacy policies before providing any personal information.
Testimonials: We may publish customer testimonials regarding our products and services. Any testimonial that includes personal data will be published only with the prior consent of the relevant data subject. If you wish to change or remove your testimonial, you may contact us using the channels indicated in this Privacy Policy.
Sharing based on consent: Where necessary, we will share your personal data with third parties only after obtaining your prior, specific, and informed consent.
Compliance with legal obligations: We reserve the right to use or disclose personal data whenever required by law, court order, or legitimate request from a competent authority, as well as where necessary to defend our rights, prevent fraud, or protect the safety of people and property. Where legally permitted, we will seek to inform the data subject in advance of such disclosure.
10. Rights of data subjects
Under the GDPR, data subjects have the following rights:
i. Right of Access – you have the right to obtain confirmation as to whether or not your personal data is being processed and, where that is the case, to access that data and obtain information about, among other things, the purposes of processing, the categories of personal data concerned, and the recipients of the data. You also have the right to obtain a copy of your personal data undergoing processing. Additional copies may be subject to a reasonable fee based on administrative costs. If the request is made electronically and unless otherwise indicated, the information will be provided in a commonly used electronic format.
ii. Right to Rectification – you have the right to obtain, without undue delay, the rectification of inaccurate personal data concerning you and to request that incomplete personal data be completed.
iii. Right to Erasure – also known as the “right to be forgotten,” you have the right to request the erasure of your personal data without undue delay whenever one of the situations provided for in the GDPR applies.
iv. Right to Withdraw Consent – whenever processing is based on consent, the data subject has the right to withdraw consent at any time, without affecting the lawfulness of processing carried out based on consent before its withdrawal.
v. Right to Object – you have the right to object, on grounds relating to your particular situation, to the processing of your personal data in the cases provided for in the GDPR. You also have the right to object at any time to the processing of your data for direct marketing purposes, in which case we will immediately stop processing it for that purpose.
vi. Right to Data Portability – you have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, as well as the right to transmit that data to another organization, where applicable under the GDPR.
vii. Right to Restriction of Processing – you have the right to obtain restriction of the processing of your personal data in certain circumstances provided for in the GDPR, including when you contest the accuracy of the personal data, for the period necessary for us to verify its accuracy, when the processing is unlawful, or when you have exercised your right to object.
viii. Right to Lodge a Complaint – the data subject has the right to lodge a complaint with a supervisory authority. In Portugal, the competent supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD).
To exercise any of the rights referred to above, you should use the contact details indicated in section 14 of this Privacy Policy.
Requests submitted will be reviewed and answered without undue delay and, in any case, within a maximum period of one month from receipt, in accordance with the GDPR. Where necessary, considering the complexity and number of requests, this period may be extended by an additional two months, and the data subject will be duly informed of the extension and the reasons for it.
11. Retention of personal data
The retention period for personal data varies depending on the purpose for which the data is processed and the respective legal bases.
Xpand IT retains personal data only for the period necessary to fulfill the purposes for which it was collected, satisfy legal, regulatory, or contractual obligations, and ensure the exercise or defense of rights in legal proceedings.
As a rule, Xpand IT will retain your personal data for a maximum period of 6 (six) years after the last contact with the data subject, unless there is a legal obligation or legitimate reason justifying retention for a longer period.
Personal data included in contracts, invoices, or other documents subject to legal archiving obligations will be retained for the legally applicable periods.
After the applicable retention periods have expired, personal data will be securely deleted or anonymized, unless its retention is required by law.
12. International transfer of personal data
Where necessary, we may transfer personal data to entities located outside the European Economic Area (EEA) or to international organizations.
In such situations, we will ensure that transfers are carried out in strict compliance with applicable personal data protection laws, including by verifying the existence of an adequate level of protection in the destination country or implementing the appropriate safeguards provided for in the GDPR.
In addition, we will adopt the necessary measures to ensure the security of the transferred data, ensuring that recipient entities are contractually required to protect the confidentiality, integrity, and availability of personal data and to use it solely for the authorized purposes.
13. Use of cookies
For more information about the use of cookies on our websites, please see our Cookie Policy.
14. Contact details for privacy matters
If you have any questions, requests, or concerns relating to this Privacy Policy or the processing of your personal data, you may contact our Data Protection Officer through the following channels:
Email: [email protected]
Phone Number: +351 21 896 7150
Address: Praça Príncipe Perfeito, No. 2, 3rd floor, 1990-278 Lisbon, Portugal
15. Changes to the Privacy Policy
Xpand IT reserves the right to amend this Privacy Policy at any time to reflect legislative, regulatory, operational, or technological changes.
Any changes will be published on our websites and will take effect from the respective publication date.
We recommend that you review this Privacy Policy periodically to stay informed about how we protect and process your personal data.
Continued use of our websites, products, or services after changes are published indicates acknowledgment of the updated version of the Privacy Policy.